secure subcall api and verb
authorJosé Bollo <jose.bollo@iot.bzh>
Thu, 13 Apr 2017 12:50:36 +0000 (14:50 +0200)
committerJosé Bollo <jose.bollo@iot.bzh>
Thu, 13 Apr 2017 21:02:25 +0000 (23:02 +0200)
Change-Id: Ia1df54bfd139f247137f4373a2cbd75dcf74efc8
Signed-off-by: José Bollo <jose.bollo@iot.bzh>
src/afb-subcall.c

index a75cbdd..68b3312 100644 (file)
@@ -89,18 +89,25 @@ static int subcall_unsubscribe(struct afb_xreq *xreq, struct afb_event event)
 static struct subcall *create_subcall(struct afb_xreq *caller, const char *api, const char *verb, struct json_object *args, void (*callback)(void*, int, struct json_object*), void *closure)
 {
        struct subcall *subcall;
+       size_t lenapi, lenverb;
+       char *copy;
 
-       subcall = calloc(1, sizeof *subcall);
+       lenapi = 1 + strlen(api);
+       lenverb = 1 + strlen(verb);
+       subcall = malloc(lenapi + lenverb + sizeof *subcall);
        if (subcall == NULL) {
                return NULL;
        }
-
        afb_xreq_init(&subcall->xreq, &afb_subcall_xreq_itf);
        afb_context_subinit(&subcall->xreq.context, &caller->context);
        subcall->xreq.cred = afb_cred_addref(caller->cred);
        subcall->xreq.json = args;
-       subcall->xreq.api = api; /* TODO: alloc ? */
-       subcall->xreq.verb = verb; /* TODO: alloc ? */
+       copy = (char*)&subcall[1];
+       memcpy(copy, api, lenapi);
+       subcall->xreq.api = copy;
+       copy = &copy[lenapi];
+       memcpy(copy, verb, lenverb);
+       subcall->xreq.verb = copy;
        subcall->caller = caller;
        subcall->callback = callback;
        subcall->closure = closure;